[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-3104Date: (C)2008-07-09   (M)2023-12-22


Multiple unspecified vulnerabilities in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allow remote attackers to violate the security model for an applet's outbound connections by connecting to localhost services running on the machine that loaded the applet.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.8
Exploit Score: 8.6
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1020459
http://marc.info/?l=bugtraq&m=122331139823057&w=2
http://www.securityfocus.com/archive/1/497041/100/0/threaded
SUNALERT-238968
BID-30140
SECUNIA-31010
SECUNIA-31055
SECUNIA-31269
SECUNIA-31320
SECUNIA-31497
SECUNIA-31600
SECUNIA-31736
SECUNIA-32018
SECUNIA-32179
SECUNIA-32180
SECUNIA-32436
SECUNIA-32826
SECUNIA-33194
SECUNIA-33236
SECUNIA-33237
SECUNIA-33238
SECUNIA-35065
SECUNIA-37386
ADV-2008-2056
ADV-2008-2740
APPLE-SA-2008-09-24
GLSA-200911-02
RHSA-2008:0594
RHSA-2008:0595
RHSA-2008:0790
RHSA-2008:0906
RHSA-2008:0955
RHSA-2008:1043
RHSA-2008:1044
RHSA-2008:1045
SUSE-SA:2008:042
SUSE-SA:2008:043
SUSE-SA:2008:045
SUSE-SR:2008:028
SUSE-SR:2009:010
TA08-193A
http://support.apple.com/kb/HT3178
http://support.apple.com/kb/HT3179
http://support.avaya.com/elmodocs2/security/ASA-2008-428.htm
http://support.avaya.com/elmodocs2/security/ASA-2008-507.htm
http://support.avaya.com/elmodocs2/security/ASA-2008-509.htm
http://www.vmware.com/security/advisories/VMSA-2008-0016.html
oval:org.mitre.oval:def:9565
sun-jre-unspecified-security-bypass(43662)

CPE    75
cpe:/a:sun:jre:1.3.1_03
cpe:/a:sun:jre:1.3.1_04
cpe:/a:sun:jre:1.3.1_05
cpe:/a:sun:jre:1.3.1_06
...
CWE    1
CWE-264
OVAL    1
oval:org.secpod.oval:def:9215

© SecPod Technologies